Re: [COSE] Stephen Farrell's Discuss on draft-ietf-cose-msg-20: (with DISCUSS and COMMENT)

Göran Selander <goran.selander@ericsson.com> Wed, 02 November 2016 19:55 UTC

Return-Path: <goran.selander@ericsson.com>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 96BC012988F; Wed, 2 Nov 2016 12:55:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.221
X-Spam-Level:
X-Spam-Status: No, score=-4.221 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5dkJTgFrdmbJ; Wed, 2 Nov 2016 12:55:31 -0700 (PDT)
Received: from sesbmg23.ericsson.net (sesbmg23.ericsson.net [193.180.251.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 50F67129889; Wed, 2 Nov 2016 12:55:30 -0700 (PDT)
X-AuditID: c1b4fb25-d35ee98000001e3e-34-581a44b0f5e7
Received: from ESESSHC022.ericsson.se (Unknown_Domain [153.88.183.84]) by (Symantec Mail Security) with SMTP id 8B.0B.07742.0B44A185; Wed, 2 Nov 2016 20:55:28 +0100 (CET)
Received: from ESESSMB303.ericsson.se ([169.254.3.133]) by ESESSHC022.ericsson.se ([153.88.183.84]) with mapi id 14.03.0319.002; Wed, 2 Nov 2016 20:55:28 +0100
From: Göran Selander <goran.selander@ericsson.com>
To: Jim Schaad <ietf@augustcellars.com>
Thread-Topic: [COSE] Stephen Farrell's Discuss on draft-ietf-cose-msg-20: (with DISCUSS and COMMENT)
Thread-Index: AQHSJ/5+PpYzxQEGkUCV86lFjxObP6Cv0hiAgArxbwCAAAG5AIABAk0AgAjA9ICAACEUAIABTcyAgAAt+4A=
Date: Wed, 02 Nov 2016 19:55:27 +0000
Message-ID: <995E9BD0-E43D-401C-830C-45B72F8ED064@ericsson.com>
References: <147665141739.25813.4419576200342341528.idtracker@ietfa.amsl.com> <029401d227f7$5cdb7fa0$16927ee0$@augustcellars.com> <e9ca5f76-e0a1-2824-4ddc-b74c416c2f0f@cs.tcd.ie> <822A08BC-5710-48E6-BCC7-AC86A554EFEC@mit.edu> <476D703F-727E-49D9-89C1-F6FD1092D55E@mit.edu> <94353594-ef7c-d909-605a-391ef2502c68@cs.tcd.ie> <D436AB37.6B4EB%goran.selander@ericsson.com> <066401d23474$a3659580$ea30c080$@augustcellars.com> <da41c9c9-6eb1-99da-227f-e37af69f0349@cs.tcd.ie> <07f701d2352c$134c3400$39e49c00$@augustcellars.com>
In-Reply-To: <07f701d2352c$134c3400$39e49c00$@augustcellars.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
Content-Type: multipart/signed; boundary="Apple-Mail-C5ECDBD0-870C-49F5-B09E-EA070B942603"; protocol="application/pkcs7-signature"; micalg="sha1"
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFjrGIsWRmVeSWpSXmKPExsUyM2J7iO4GF6kIg4vLtCzebd3HaDFt61RW i95HtxktZvyZyGyxevp3NosN116yWkzfe43dgd1j45zpbB5ru6+yeSxZ8pPJo+nMUeYAligu m5TUnMyy1CJ9uwSujH+/NzEWXNKv6N/1jLmBcZ5eFyMnh4SAicTLt7/YQGwhgXWMEoe2CXYx cgHZixklpm3ZCZZgE3CReNDwiAnEFhFQl9i6+iYTSBGzwH9GiSUvOthBEsICqRJXWs9BFaVJ nHg8hRHCTpJ4Mv8CSxcjBweLgIrEhsvhIGFeAXuJG8dnskEsm8kicWztW7B6TgEHiZ43t8Bm MgqISXw/tQZsJrOAuMStJ/OZIK4WkXh48TQbhC0q8fLxP1aIgyYzSjS/2cAIsUFQ4uTMJywT GIVnIemfhaxuFpI6iCJNif3dy6FsRYkp3Q/ZIWxriRm/DrJB2KYSr49+ZERWs4CRYxWjaHFq cVJuupGxXmpRZnJxcX6eXl5qySZGYIwe3PJbdQfj5TeOhxgFOBiVeHgL/ktGCLEmlhVX5h5i VAGa82jD6guMUix5+XmpSiK8WcDIF+JNSaysSi3Kjy8qzUktPsQozcGiJM5rtvJ+uJBAemJJ anZqakFqEUyWiYNTqoGxMtTeomGB7Oqp2cL94o/zm8r4gwyikzZayEp/WnV/09MZLsadRzuZ Cuf3/HEx9Zvdsm/PDH+RExUfpH1nvlk6oVPhTm/jGXv5o55Bj8y/KL1dYyptVG3p//GU8vE/ vwSVYmIEupZ+jC349apdsWi1S9AqNz3GQ/yMl+6FXj7z7yzbXsejrseVWIozEg21mIuKEwHf DwSj2QIAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/2gXFi8fowl_vvaR63iDoEvqZgHQ>
Cc: Justin Richer <jricher@mit.edu>, "cose-chairs@ietf.org" <cose-chairs@ietf.org>, The IESG <iesg@ietf.org>, "draft-ietf-cose-msg@ietf.org" <draft-ietf-cose-msg@ietf.org>, Stephen Farrell <stephen.farrell@cs.tcd.ie>, "cose@ietf.org" <cose@ietf.org>
Subject: Re: [COSE] Stephen Farrell's Discuss on draft-ietf-cose-msg-20: (with DISCUSS and COMMENT)
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Nov 2016 19:55:32 -0000


> On 2 nov. 2016, at 18:11, Jim Schaad <ietf@augustcellars.com> wrote:
> 
> 
> 
>> -----Original Message-----
>> From: Stephen Farrell [mailto:stephen.farrell@cs.tcd.ie]
>> Sent: Tuesday, November 01, 2016 2:16 PM
>> To: Jim Schaad <ietf@augustcellars.com>; 'Justin Richer' <jricher@mit.edu>
>> Cc: cose-chairs@ietf.org; cose@ietf.org; 'The IESG' <iesg@ietf.org>; draft-ietf-
>> cose-msg@ietf.org
>> Subject: Re: Stephen Farrell's Discuss on draft-ietf-cose-msg-20: (with DISCUSS
>> and COMMENT)
>> 
>> 
>> Hiya,
>> 
>>> On 01/11/16 19:17, Jim Schaad wrote:
>>> Another thread dealing with this issue includes
>>> https://www.ietf.org/mail-archive/web/cose/current/msg00981.html  -
>>> basically the subject is 'make "alg" field optional'
>>> 
>>> Usual suspects (Göran, Ludwig, Francesca) on one side, me and a
>>> couple of others on the other side.  Interestingly the antis included
>>> Mike who argued for this in the JOSE.
>> 
>> Heh. To be honest, I'm not sure what's best here. Normally if
>> it were just my design tastes against the WGs, I'd happily
>> fold. But in this case we have an appendix that says how to
>> not do what's a MUST in the body of the spec. And I suspect
>> that this could damage interop depending on whether or not
>> libraries follow the MUST or not.
>> 
>> Do we think there's a way to square this circle and somehow
>> get rid of the appendix to get to a result folks can all use?
> 
> I wish I knew.  The fact that the CORE draft is not even complying with how the appendix is saying to do things almost leads me to think that we should just kill that section of the appendix and re-evaluate things. 

I'd like to understand what is the problem with how it is specified in the  CORE draft, if it is a problem. If it isn't, then either stop mandating alg + remove app A, or change Appendix A so that this case isn't discouraged. 

Göran